- Provider
- Microsoft-Windows-EventForwarder
- Channel
- Operational
Example Event #
{
"system": {
"provider": "Microsoft-Windows-EventForwarder",
"guid": "",
"event_source_name": "",
"event_id": 111,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": 0,
"time_created": "2021-04-27T15:03:16.983Z",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Microsoft-Windows-EventForwarder/Operational",
"computer": "dhcp01.offsec.lan",
"security": {
"user_id": ""
}
},
"event_data": {}
}